The flaw was reported by Google's Threat Analysis Group and was likely exploited by a commercial spyware vendor.